There are two things which I think will change that game substantially:
1. As this is taken more seriously, companies trying to stay in compliance with the law are going to be enforcing KYC strictly. That's going to make it harder to use things like tumblers because not only will you be paying more to use the service but you'll also be getting tainted tokens which an increasing fraction of businesses either won't accept at all or will accept at a discount rate to compensate for the decreased utility. I think that ratchet effect is going to really limit future services like Tornado Cash: when there's a non-trivial risk involved for using it fewer people will participate and those who do will expect to be paid more.
2. These services depend on liquidity because anonymity is a function of how many people are running money through it. The Treasury department doesn't really care if you and and a few curious friends set up a proof-of-concept instance because unless you can also pump the equivalent of millions of dollars into the system it won't be used by the people they're concerned about (ransomware gangs, North Korea, etc.) since it would take millennia to launder money at their scale. This is similar to how the goal for counterfeiting paper money isn't set to “impossible” but rather accepted at a low frictional level as long as it's too risky for anyone to attempt a sufficiently large-scale counterfeiting operation which could actually impact the overall economy.
This is for the courts to decide I guess
Of course as a practical matter it can be difficult to prosecute DDoS attackers under that statute. Either they don't leave hard evidence, or they hide in countries which don't extradite.
The applicable legal test is from United States v. O'Brien [2], which ruled that even though burning a draft card may be expressive speech, the government's interest in draft cards not getting burnt allows them to forbid it without falling afoul of the first amendment.
Junger v. Daley was cited as precedent in Universal City Studios v. Reimerdes [3], where the courts ruled that the functional power of DeCSS being illegal under the DMCA was sufficient to justify banning the distribution of the DeCSS source code.
[1] https://en.wikipedia.org/wiki/Junger_v._Daley
[2] https://en.wikipedia.org/wiki/United_States_v._O%27Brien
[3] https://en.wikipedia.org/wiki/Universal_City_Studios,_Inc._v...
Speech is speech, code can be spoken, and it can also be executed. The former is speech, the latter is action. Making API calls and flipping bits in a computer is what crosses the line from one to the other.
Yes? This is entirely reasonable if we analogize it to how fiction often approaches it. There might be some evil book, a necronomicon, or killing spells like in Harry Potter. In many fictional media, people are allowed to learn such spells, they're just not allowed to say the spells out loud. Reading and writing a spell is not the same as saying it and thereby executing it.
It doesn't solve Congress’ mandate to the Treasury where OFAC is used against entities that can appeal their own listing on the sanctions list. The smart contracts cannot currently do that.